Release date: 26 November, 2025Change typeChangesAdded a new Low Analytics BIOCClickFix - PowerShell executed through the run applicationAdded a new Low Analytics AlertSuspicious activity indicating a potential abuse of a cloud-native email serviceAdded 22 new Informational Analytics BIOCsA Microsoft Teams application was installedA Microsoft Teams bot was added to a teamA rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft processAWS Backup recovery point deletionAWS EBS snapshot deletionAWS S3 object deletionAWS SSM parameters discoveryAWS SSM parameters retrievalAWS Secrets Manager AccessAWS Secrets Manager discoveryBucket's object ownership controls were modifiedExternal user added a link to a Microsoft Teams chatForeign account was granted permissions to S3 bucket via resource-based policyGCP administrative role granted to a cloud identityMicrosoft Teams application setup policy was modifiedMicrosoft Teams external communication policy was modifiedMicrosoft Teams messages were exported from conversationNew Teams application published to the organization catalogUncommon Launch Daemon persistency was registered or modifiedUncommon attempt at discovering a sensitive fileUncommon recurring rare external host accessUser installed an application in Microsoft Teams via Graph APIAdded 4 new Informational Analytics AlertsExternal user created a Microsoft Teams conversation with suspicious operationsExternal user started a Microsoft Teams conversationUser exported multiple messages in Microsoft Teams via Graph APIUser sent messages in Microsoft Teams to multiple conversations via Graph APIImproved logic of a High Analytics BIOCSuspicious SaaS API call from a Tor exit nodeImproved logic of a Medium Analytics BIOCKubernetes vulnerability scanning tool usageImproved logic of 14 Low Analytics BIOCsAbnormal communication with a rare combination of TLS and HTTP User AgentEmail attachment with Right-to-Left Override Unicode characterEmail was received from an unknown sender using a disposable domainKubernetes pod creation from unknown container image registryRare RDP session to a remote hostRare process executed by an AppleScriptRecurring access to rare IPRecurring access to rare domainRecurring rare domain access from an unsigned processUncommon SSH session was establishedUncommon file access over WebDAVUnusual process accessed a crypto wallet's filesUnusual process accessed a messaging app's filesUnusual process accessed a web browser history fileImproved logic of 19 Low Analytics AlertsA compromised process accessed a rare external hostA user uploaded malware to SharePoint or OneDriveAbnormal RPC traffic to multiple hostsAbnormal SMB activity to multiple hostsAbnormal sensitive RPC traffic to multiple hostsFailed ConnectionsFailed DNSHTTP with suspicious characteristicsImpossible traveler - SSOImpossible traveler - VPNLarge Upload (Generic)Logs were not collected from a data source for an abnormally long timeMicrosoft 365 storage services exfiltration activityMultiple Azure AD admin role removalsRisk indicators detected in emailSpam Bot TrafficSuspicious ICMP traffic that resembles smurf attackSuspicious identity downloaded multiple objects from a bucketUser added to the SMS Admins local groupImproved logic of 118 Informational Analytics BIOCsA Kubernetes ConfigMap was created or deletedA Kubernetes Cronjob was createdA Kubernetes DaemonSet was createdA Kubernetes Pod was created with a sidecar containerA Kubernetes Pod was deletedA Kubernetes ReplicaSet was createdA Kubernetes StatefulSet was createdA Kubernetes cluster role binding was created or deletedA Kubernetes deployment was createdA Kubernetes ephemeral container was createdA Kubernetes namespace was created or deletedA Kubernetes node service account activity from external IPA Kubernetes role binding was created or deletedA Kubernetes secret was created or deletedA Kubernetes service account executed an unusual API callA Kubernetes service account has enumerated its permissionsA Kubernetes service account was created or deletedA Kubernetes service was created or deletedA possible risky login to AzureAWS Storage Gateway enumerationAWS Storage Gateway file share enumerationAWS user creationAbnormal Communication to a Rare DomainAbnormal Recurring Communications to a Rare DomainAn Azure application reached a throttling API rateAn identity accessed a cloud storage for the first timeAn identity accessed cloud storage containing sensitive dataAn identity attached an administrative policy to an IAM user or roleAppleScript executed a shell scriptAppleScript interpreter dynamic library loaded into a processAttempted Azure application access from unknown tenantAuthentication method was added to Azure accountAzure Service principal/Application creationAzure conditional access policy creation or modificationAzure group creation/deletionAzure mailbox rule creationAzure user creation/deletionAzure user password resetCredentials were added to Azure applicationDLP sensitive data exposed to external usersDenied API call by a Kubernetes service accountEmail attachment with a potentially malicious file extensionEmail attachment with multiple extensionsEmail attachment(s) with potentially malicious MIME typeEmail containing a link with an IP address convention was detectedEmail containing a redirected linkEmail contains URL delivering high-risk file typeEmail has a short body or subject and was sent from an external sourceEmail marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level valuesEmail mimics replies or forwards without an actual ongoing conversationEmail was received from an unknown address using a public provider domainEmail was received from an unknown sender using a recognized domainEmail with URL shortener detectedEmail with file-sharing link containing auto-download parameterExternal email display name impersonation of internal personnelExternal email with a single internal recipient hidden in BCCExternal user invitation to Azure tenantFirst SSO Resource Access in the OrganizationFirst-seen email from mailbox owner to external recipient's address in the last 30 daysGCP Service Account creationIAM instance profile associations were describedIAM instance profile was associated with EC2 instanceIAM instance profile was createdIAM instance profile was replaced for EC2 instanceIAM instance profiles were listedIAM policy was attached to roleIAM role-attached managed policies were listedKubernetes Pod Created With Sensitive VolumeKubernetes Pod Created with host Inter Process Communications (IPC) namespaceKubernetes Pod created with host process ID (PID) namespaceKubernetes Privileged Pod CreationKubernetes admission controller activityKubernetes cluster events deletionKubernetes network policy modificationKubernetes pod creation with host networkKubernetes secret enumeration activityKubernetes service account activity outside the clusterMoniker link detected in URL(s)OneDrive file downloadOneDrive file uploadOneDrive folder creationOutbound email contains file-sharing service link sent to external recipientOutbound email includes an external BCC recipient observed for the first timeOwner was added to Azure applicationPenetration testing tool attemptPossible IPFS traffic was detectedPotential spoofing of internal domain spottedPrivileged role used by Azure applicationPunycode characters detected in URL(s)Rare AppID usage to a rare destinationRare DLP rule match by userRarely seen URL(s) within a well-known domain detected in your organization's emailSaaS suspicious external domain user activitySuspicious DKIM ResultSuspicious DMARC resultSuspicious SPF ResultSuspicious Unicode character detected in emailUncommon Launch Agent persistency was registered or modifiedUncommon URL domain(s) in your organization detected in emailUncommon attempt at grabbing credentials from a sensitive fileUnpopular URL(s) detected in emailUnpopular domains detected in email URLs for a recipientUnrecognized internal address (AAD mismatch)Unsigned DLL Hijack into a Microsoft processUnusual Kubernetes secret accessUnusual access to Microsoft 365 storage servicesUnusual cloud identity impersonationUnusual exec into a Kubernetes PodUnusual hostname for the sending mail server in the email headersUnusual process accessed a macOS notes DB fileUnusual process accessed web browser cookiesUnusual process accessed web browser credentialsUnusual resource access by Azure applicationUsage of homograph characters detected in an emailUsage of homograph characters detected in an email attachment(s) nameUsage of homograph characters detected in an email's from headerUser accessed SaaS resource via anonymous linkX-Forefront-Antispam-Report has flagged this email as a potential threatImproved logic of 40 Informational Analytics AlertsA compromised process accessed a rare cloud resourceAbnormal Allocation of compute resources in multiple regionsAbnormal RDP connections to multiple hostsAbnormal SMB scanning activity to multiple hostsAbnormal connections to a dormant host from a newly seen endpointAllocation of multiple cloud compute resourcesAn Azure identity performed multiple actions that were deniedAzure enumeration activity using Microsoft Graph APIAzure uncommon increase in API request sizesCloud user performed multiple actions that were deniedDeletion of multiple cloud resourcesKubernetes enumeration activityLog enumeration via cloud native logging serviceMailbox enumeration activity by Azure applicationMassive file downloads from SaaS serviceMicrosoft OneDrive enumeration activityMicrosoft OneNote enumeration activityMicrosoft SharePoint enumeration activityMicrosoft Teams enumeration activityMultiple Okta MFA requests sent to a userMultiple cloud snapshots exportMultiple failed logins from a single IPNumerous emails sent by a single sender to multiple internal recipientsOkta Reported Threat DetectedOkta account reset password attemptOkta account unlockOkta device assignmentPort ScanPossible Privilege Escalation using Delegated MSA accountPotential NTLM Relay AttackRare access to known advertising domainsSSO Password SprayShort-lived Azure AD user accountSingle account excessively locked outStorage enumeration activityUncommon WPAD queriesUnusual SSH ActivityUnusual attachment volume in outbound emailsUpload pattern that resembles Peer to Peer trafficUser and Group Enumeration via SAMRIncreased the severity to Low for 2 Analytics BIOCsModification of NTLM restrictions in the RegistrySending unusual file(s) to an external addressDecreased the severity to Informational for an Analytics BIOCRemote usage of an Azure Service Principal tokenDecreased the severity to Informational for an Analytics AlertSuspicious secrets dump activityChanged metadata of 2 Medium Analytics BIOCsLogging was impaired via external encryption keyPhantom DLL LoadingChanged metadata of 4 Low Analytics BIOCsContained process execution with a rare GitHub URLPossible DLL Search Order HijackingSuspicious access of the System Management ContainerUncommon remote monitoring and management toolChanged metadata of a Low Analytics AlertUser collected remote shared files in an archiveChanged metadata of 10 Informational Analytics BIOCsAn EBS snapshot block was downloadedCloud access key creationExecutable moved to Windows system folderGlobally uncommon high entropy process was executedGlobally uncommon image load from a signed processPossible DLL Hijack into a Microsoft processPossible DLL Side-LoadingRare signature signed executable executed in the networkUncommon access to cloud platforms' sensitive files by a scripting engineUnusual use of a 'SysInternals' toolChanged metadata of 4 Informational Analytics AlertsA user performed suspiciously massive file activityA user printed an unusual number of filesPossible data exfiltration over a USB storage devicePossible internal data exfiltration over a USB storage device